Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Keyloggers
Mar 10, 2026
3 Mins Read
Sep 11, 2026

What Is a Keylogger?

A keylogger records keyboard input on a computer or mobile device. Attackers use keylogging to capture passwords, payment details, messages, search terms, and other information entered by a user. Monitoring can be implemented through malware, a malicious browser component, operating-system hooks, firmware, or a physical device.

Some keylogging is legitimate when it is disclosed and authorized for troubleshooting, accessibility, or monitored business use. It becomes a security threat when collection occurs without informed authorization or when an attacker abuses a legitimate monitoring capability.

Key Takeaways

  • Keyloggers can be software-based, browser-based, kernel-level, mobile, or physical.
  • Captured keystrokes often expose credentials before encryption protects the resulting network session.
  • Detection requires endpoint, browser, mobile, identity, and physical-security context.
  • Password changes should occur from a trusted device after the collection mechanism is removed.
The main stages and decision points associated with keylogger.
The main stages and decision points associated with keylogger.

How a Keylogger Works

A software keylogger may arrive through phishing, a Trojan, a malicious installer, an extension, or post-compromise tooling. It records input through application hooks, browser access, accessibility features, or lower-level system components.

Collected data is stored locally or sent to attacker infrastructure. More capable spyware may pair keystrokes with screenshots, clipboard content, window titles, form data, and session information to make the capture easier to interpret.

Common Types and Techniques

  • User-mode and application-hook keyloggers
  • Kernel, driver, and boot-level keyloggers
  • Browser extensions and form-grabbing malware
  • Hardware implants and malicious peripherals

Security and Business Risks

  • Credential and financial theft
  • Exposure of confidential communications
  • Account takeover and session compromise
  • Persistent surveillance of employees or executives
Common keylogger risks paired with practical defensive controls.
Common keylogger risks paired with practical defensive controls.

Warning Signs and Detection

Investigate unfamiliar processes, drivers, extensions, accessibility permissions, input hooks, scheduled tasks, startup items, and outbound traffic. Physical inspection matters for shared workstations, kiosks, and high-risk environments.

Prevention and Response

Use endpoint and mobile protection, restrict installation and administrator rights, manage browser extensions, patch systems, use phishing-resistant MFA, secure work areas, and allow only trusted peripherals. Rebuild a system when integrity cannot be established.

How SOCRadar Can Help

SOCRadar combines external asset visibility, threat intelligence, Dark Web monitoring, vulnerability context, and indicator enrichment to help teams identify exposure and investigate activity connected to keylogger.

Explore SOCRadar Dark Web Monitoring or request a demo to strengthen threat-informed prevention and investigation.

Frequently Asked Questions

Can a keylogger capture passwords?

Yes. A keylogger can record a password as it is typed, before the application hashes it or the network connection encrypts it.

Does an on-screen keyboard stop keylogging?

It may defeat a basic keyboard hook, but spyware can capture clicks, screenshots, clipboard data, forms, or accessibility events. It is not a complete defense.

What should a victim do first?

Disconnect the suspected device if active compromise is likely. Use a separate trusted device to reset important credentials and revoke sessions after the keylogger has been contained.

Are all keyloggers illegal?

No. Authorized and disclosed monitoring can have legitimate uses. Secret interception, unauthorized installation, or misuse of captured information can violate policy and law.